Roadmap

What's open.

No dates. Each item links to its issue, where the work is actually tracked. Synced 2026-09-28.

Latest release

v0.1.0, released 2026-09-25

What changed in it, and since: the changelog.

Platforms

PlatformStatus
linux/amd64 fully tested in CI
macOS/arm64 verified locally on 2026-09-27
linux/arm64 a nightly subset
macOS/amd64 smoke-installed
Windows unsupported (WSL2 untested)

From docs/status.md on main.

On main, next release next release

Merged on main and not in v0.1.0. Each line is the lead of its [Unreleased] entry in the changelog.

Added

  • A terminal in the console's top bar, like Cloud Shell (#781)
  • A release is latest only once its smoke test has passed (#680)
  • A release is built only from a commit CI has passed (#596)
  • The macOS binaries can be signed and notarized (#605)
  • cloudburrow prefetch and up --offline (#604)
  • The local-AI runtime image is published with each release (#602)
  • CloudBurrow's own Cloud Storage server (#519)
  • Cloud Storage verified through the official Python client (#516)
  • Cloud KMS through cloudburrow terraform (#425)
  • Cloud KMS automatic rotation (#816)
  • A Cloud KMS oracle comparing the resource RPCs and the version lifecycle against a pinned fakekms, run nightly (#419, #420)
  • A release smoke test (#603)
  • This changelog, and SECURITY.md with how to report a vulnerability (#603)
  • RSA signed URLs verify on an up instance (#577)

Changed

  • --mode ephemeral now also applies to Cloud KMS (#481)
  • up creates the managed namespace whenever the cluster is up, not only with a backend (#571)
  • A Cloud Run revision that fails at startup is reported after 240s rather than Knative's 600s (#568)
  • Secret Manager refuses the create fields it would drop (ttl, rotation, topics and others), refuses list filters, compares request etags, and verifies and returns payload CRC32C (#580)
  • Cloud Tasks refuses OIDC and OAuth tokens, logging config and list filters it would drop, keeps dispatch_deadline and honours max_retry_duration (#578)
  • The embedded storage servers are no longer committed (#585)
  • Release notes are taken from this changelog instead of fixed text (#603)
  • The rendered Homebrew formula no longer sets a version that repeats the one in its URLs (#603)
  • A fault rule on Cloud Tasks' ListQueues, Secret Manager's ListSecrets or Cloud Scheduler's ListJobs now also fails that service's console list, with the message an SDK receives, and a console open on the screen draws from the rule's count (#594)
  • The console is tested in headless Chrome in CI (test/browser, chromedp) (#594)

Fixed

  • A CLI built without the embedded Cloud Storage server (a plain go build or go install) is refused before up creates a cluster, naming the fix, rather than after kind has spent minutes creating one (#686)
  • Port forwarding replaces a dead tunnel on evidence rather than on one client's failure (#526)
  • The setup-cloudburrow action works with the CLI it installs (#679)
  • Both Linux release archives are linked the same way (#714)
  • Container engines are stated, and an engine whose kind gateway is not on this machine fails early (#712)

Security

  • Every /admin route now requires a per-instance token (#553)
  • Every HTTP listener refuses a request whose Host is not an IP address, localhost (or a name under .localhost), host.docker.internal, cloudburrow-host.<namespace>.svc.cluster.local or, on the builtin storage server, its Service and virtual-hosted bucket names, answering 421 with the rejected host named (#676)
  • The builtin Cloud Storage server refuses a browser request from an origin that is neither loopback (localhost, *.localhost, 127.0.0.1, [::1], any port) nor named with the new up --cors-allow-origin (CLOUDBURROW_CORS_ALLOW_ORIGIN, config storage.corsAllowOrigins), answering 403 with no CORS headers, preflights included (#677)

Open work

Terminal 0 open

#834, #824, #826 (closed since sync)

Console parity 1 open

  • #782 Console parity audit: every feature CloudBurrow implements is reachable from the UI Open View issue

#787, #788, #789, #791, #793, #797, #798, #799 (closed since sync)

Storage 0 open

#828, #829 (closed since sync)

Cloud Run Jobs 0 open

#582 (closed since sync)

Release 1 open

  • #605 Sign and notarize the macOS release binaries and document Gatekeeper handling Open View issue

#601 (closed since sync)

AI 1 open

  • #41 Local AI: Google EmbeddingGemma inference and embedding API Open View issue

Honesty and licensing 1 open

  • #684 Resolve the console's shipped Google product icons against parity §1/§2 and NOTICE Open View issue

#678 (closed since sync)

Bugs 0 open

#780, #820 (closed since sync)

Dependencies 1 open

  • #264 Hold google.golang.org/grpc at v1.83.2 until a release fixes GO-2026-6443 Open View issue

See the project board on GitHub

Build against Google Cloud APIs, locally

Free and open source under Apache-2.0. No account, no sign-up, no Google Cloud bill.

Get started